[Freeipa-devel] [PATCH] 0174-0175 ipa-kdb fixes

Martin Kosek mkosek at redhat.com
Mon Feb 16 15:32:30 UTC 2015


On 02/13/2015 08:58 AM, Martin Kosek wrote:
> On 01/26/2015 04:44 PM, Simo Sorce wrote:
>> On Wed, 21 Jan 2015 12:03:48 +0200
>> Alexander Bokovoy <abokovoy at redhat.com> wrote:
>>
>>> Hi,
>>>
>>> couple patches to fix Kerberos DAL driver in relation to trusts.
>>>
>>> Patch 0174:
>>> Allow using CA paths defined in krb5.conf on top of what we define
>>> automatically for trusted domains.
>>> https://fedorahosted.org/freeipa/ticket/4791
>>>
>>> Patch 0175:
>>> Change error code reported back to Kerberos client when a principal
>>> from a disabled trusted domain attempts to access resources we
>>> control.
>>>
>>> The error code will help older SSSD to properly reflect error message
>>> in the PAM stack.
>>> https://fedorahosted.org/freeipa/ticket/4788
>>>
>>
>>
>> They both LGTM.
>>
>> Simo.
>>
> 
> Is that an ACK then? Sumit, were you able to test those by any chance?
> 
> Thanks,
> Martin
> 

Sumit confirmed he tested them, so it is an ACK.

Pushed to master, ipa-4-1.

Martin




More information about the Freeipa-devel mailing list